api-design-reviewer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and Python tools (
api_linter.py,api_scorecard.py,breaking_change_detector.py) for evaluating API designs. The scripts use standard Python libraries to perform structural and semantic checks on JSON-based API specifications. - [INDIRECT_PROMPT_INJECTION]: The skill scripts ingest untrusted external data in the form of OpenAPI/Swagger JSON files.
- Ingestion points: The scripts
scripts/api_linter.py,scripts/api_scorecard.py, andscripts/breaking_change_detector.pyaccept file paths to API specifications as CLI arguments and load them usingjson.load(). - Boundary markers: None present; the scripts parse the provided files directly.
- Capability inventory: The scripts are restricted to file reading/writing (to user-provided output paths) and logic-based analysis. They do not utilize network libraries,
eval,exec, orsubprocessfor dangerous operations. - Sanitization: The scripts use standard JSON parsing which ensures basic data integrity, followed by structural validation logic.
Audit Metadata